Skip to main content
Rule Updates

CISA Published the Logging Reference Architecture — and Contractor-Operated Systems Are In Scope

CISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14, which rescinded M-21-31 and put federal civilian agencies on a maturity clock for how they log, retain, and produce network data. The memorandum reaches systems operated “by third parties on the agency’s behalf” — so contractor-run systems are inside the agency’s plan, and the obligation will arrive through contract terms rather than the memo itself.

Brandon Hancock, J.D., CMMC-RPPublished August 27, 2026Updated August 27, 20267 min read

On August 20, 2026, the Cybersecurity and Infrastructure Security Agency published the Logging Reference Architecture, the implementing guidance required by Office of Management and Budget Memorandum M-26-14. Federal civilian executive branch agencies must submit an Agency Logging Plan to OMB and CISA by November 18, 2026, and CISA has provided a plan template to structure it. The memorandum behind it applies to information systems "owned or operated by the agency or by third parties on the agency's behalf" — which is where government contractors enter the picture.

What M-26-14 Changed

OMB issued Memorandum M-26-14, "Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats," on May 22, 2026, over the signature of Director Russell T. Vought. It rescinded M-21-31 effective immediately.

OMB's stated reason for the change is worth reading carefully, because it explains the shape of what replaced it. M-21-31 "improved foundational capabilities across agencies," but some requirements — notably "the retention of vast quantities of logging data without clear utility" — "proved neither operationally feasible nor cost-effective for most agencies." The replacement directs a "risk-based, prioritized logging approach" organized around two objectives:

  • Continuous Event Monitoring (CEM): logging infrastructure that lets an agency monitor network activity in real time, flag anomalous activity promptly, and respond in a timely manner — typically ingested by a Security Operations Center.
  • Threat Hunting, Investigation, Response, and Forensics (THIRF): the ability to investigate and perform forensic analysis after a known or suspected compromise, which requires "sufficient hot and cold storage as well as the capability to retrieve and centralize logging data from multiple sources."

The minimum baseline is now six months actively searchable and one year retrievable. Storage may be decentralized, but logs must be "readily available to the top-level agency security operations center." Timestamps must be accurate and synchronized to a traceable time source. Appendix B lists eleven categories of activity the logs must support, from identifying the identity performing an operation to determining the attack vectors used for initial access and lateral movement.

The Part That Reaches Contractors

Three provisions do the work.

Scope follows the system, not the operator. M-26-14 requires each agency to pursue CEM and THIRF "with respect to all information systems owned or operated by the agency or by third parties on the agency's behalf," expressly including IoT devices and operational technology that form part of such a system. A contractor-operated system is an agency system for this purpose.

Maturity is measured per system, on a clock. Appendix C sets a five-level maturity model scored across inventory visibility, collection coverage, collection operations, data retention, and log management — and overall maturity is "calculated based on the lowest watermark for each component." Agencies must reach Level 1 within 120 days of the Logging Reference Architecture's release, Level 2 within 180 days, and Level 3 within 320 days. Measured from the August 20, 2026 publication, that is roughly December 2026, February 2027, and July 2027. Level 2 requires that required logs be searchable and retrievable for at least 80% of the hardware and software assets in the system inventory; Level 3 raises that to 90% and adds encryption in transit and at rest with regular hashing for veracity. An agency cannot report those numbers for a system it does not operate without getting them from the party that does.

Logs must be producible to CISA and the FBI. In the event of a known or suspected compromise of one or more federal networks, agencies "shall provide logs and other relevant data to CISA and the Federal Bureau of Investigation (FBI) upon request," in an agreed format and, to the greatest extent practicable, within the timeframes requested. If your system holds the logs, your incident-response process is the mechanism by which the agency satisfies that obligation.

An Important Limit — This Is Not a DoD Rule

M-26-14 does not apply to national security systems as defined in 44 U.S.C. § 3552(b)(6), or to Department of Defense and Intelligence Community systems described in 44 U.S.C. § 3553(e). This is a civilian-agency policy. It does not change DFARS 252.204-7012, CMMC scoping, or your SPRS score. Treat it as a separate obligation stream that attaches to civilian work — much like CISA's BOD 26-04 patching directive, which likewise binds agencies directly and reaches contractors only through the contract.

That distinction matters in the other direction too. Because the obligation is agency-facing, nothing lands on you until an agency writes it into a solicitation, a contract modification, or a task order — and agencies working toward a November 18 plan and a December Level 1 milestone have a strong incentive to write quickly.

What to Do Now

Find out whether you hold agency logs. Any system you operate on a civilian agency's behalf — hosted application, managed service, cloud environment, connected device deployment — is in scope of the agency's plan. Find My Requirements is built for tracing which of your contracts carry which obligations.

Inventory before you are asked. Level 1 requires 70% of IT/OT/IoT assets in a centralized hardware and software inventory; Level 3 requires 90% updated daily. Asset inventory is the constraint on every level above it, and it is the slowest thing to build. The build-a-program guide covers sequencing that work.

Price retention against the actual floor. Six months searchable and twelve months retrievable is cheaper than what M-21-31 demanded, but coverage percentages are now the binding constraint. Do not agree to legacy retention terms out of habit, and do not assume the old numbers still apply.

Get the log-production path written down. Decide now who pulls logs, in what format, and how fast, and put it in the incident-response section of your program documentation. A request that arrives during an active compromise is not the moment to design the workflow.

Watch the contract, not the memo. As with OMB's rescission of the governmentwide software attestation mandate, the operative text for a contractor is in the solicitation. The frameworks reference explains where logging and monitoring controls sit relative to the standards you already implement.

Key Takeaways

  • CISA published the Logging Reference Architecture on August 20, 2026, implementing OMB Memorandum M-26-14 (May 22, 2026), which rescinded M-21-31 and replaced prescriptive retention with a risk-based approach built on continuous event monitoring and threat hunting/forensics; agency logging plans are due to OMB and CISA by November 18, 2026.
  • The memorandum covers systems operated "by third parties on the agency's behalf," and its maturity model — Level 1 within 120 days of the architecture's release, Level 2 within 180, Level 3 within 320 — is measured per system, so contractor-operated systems will be pulled into agency reporting through contract terms and data calls.
  • M-26-14 excludes national security systems and DoD/IC systems, so this is a civilian-agency obligation stream that runs alongside, not inside, DFARS and CMMC requirements — and the practical trigger for any contractor is the solicitation or contract modification, not the memorandum itself.
Share
BH

Brandon Hancock

J.D. · CMMC Registered Practitioner (RP)

Brandon is the founder and principal advisor of GovConCyber. His advisory approach is shaped by roughly six years as a U.S. Army human intelligence collector, where information accuracy, source protection, classification discipline, need-to-know access, and controlled reporting were daily requirements. He brings that information-discipline mindset to GovConCyber's work helping government contractors understand and comply with federal cybersecurity obligations.

Was this post helpful?